Information Security Analyst, Mid-Level – DevSecOps

Posted 16hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

DevSecOps analyst securing AWS environments and CI/CD pipelines for SGA’s corporate systems. Automating vulnerability remediation, secrets management, and Secure by Design practices.

Responsibilities:

  • Support the development team in implementing DevSecOps and Secure by Design practices
  • Design, implement, and enhance CI/CD pipelines, incorporating security controls into the development process
  • Integrate security tools into pipelines, including SAST, DAST, SCA, and container vulnerability scanning
  • Automate security controls and processes
  • Identify and remediate vulnerabilities in applications, dependencies, packages, images, and components
  • Support the remediation of vulnerabilities identified by security tools, scanners, and technical assessments
  • Implement security improvements in AWS environments, including services, configurations, permissions, networks, and resources
  • Assess security configurations and propose improvements for AWS resources
  • Support the hardening of systems, servers, containers, and infrastructure components
  • Support the secure management of secrets, credentials, keys, and certificates
  • Implement controls to prevent the exposure of credentials and sensitive information in source code, pipelines, and development environments
  • Collaborate with developers, DevOps, infrastructure, and security teams to embed security throughout the development lifecycle
  • Support the creation and continuous improvement of security standards and best practices for development and cloud environments
  • Document implemented configurations, procedures, standards, and improvements

Requirements:

  • Professional experience in Information Security, DevSecOps, Cloud Security, or related fields
  • Hands-on experience with AWS
  • Knowledge of CI/CD and experience with at least one pipeline platform, such as GitHub Actions, GitLab CI/CD, Azure DevOps, Jenkins, or a similar tool
  • Knowledge of Git and software development workflows
  • Knowledge of security in Linux systems
  • Knowledge of Docker and containers
  • Knowledge of secrets, credentials, keys, and certificate management
  • Basic to intermediate knowledge of IAM and cloud access control
  • Familiarity with SAST, DAST, SCA, and container scanning concepts
  • Ability to analyze security issues and implement the corresponding remediation measures
  • Collaborative approach and ability to work closely with development teams